A7A5 Sanctions: $179.1B Stablecoin Crackdown Explained

Article author
Angelina Manko
Head of Legal & Regulatory Affairs

Treasury designated the Russia-linked A7 Network as a significant transnational criminal organization on October 1, 2026, while FinCEN identified at least $179.1 billion in gross on-chain A7A5 stablecoin movement between February 2025 and June 2026. The coordinated action under Operation Economic Outcast combines immediate OFAC blocking requirements with a proposed transfer prohibition that would reach fiat and crypto transactions involving non-public A7 Network Sub-Agents.

Key takeaway: The A7A5 sanctions action is not merely a token designation. It extends compliance exposure from identifiable A7 Network entities to an evolving network of controlled foreign Sub-Agents, including activity involving convertible virtual currency, wrapped assets, OTC counterparties, and administered crypto addresses.

The $179.1 billion figure needs careful interpretation. More than 180 entities processed that amount of A7A5 transactions, but it represents gross token movement rather than trade value. FinCEN states that A7A5 served as an internal accounting mechanism, including transfers across internal addresses used to maintain a balanced ledger. Separately, A7 Network Sub-Agents processed more than $17 billion in fiat bank payments between January 2025 and June 2026.

What did Operation Economic Outcast change for A7A5 compliance?

Operation Economic Outcast changed A7A5 compliance by pairing immediate OFAC blocking obligations for the A7 Network with FinCEN’s proposed 31 CFR 1010.668, which would prohibit covered institutions from transmitting fiat or convertible virtual currency involving any A7 Network Sub-Agent. The October 1, 2026 action therefore targets both the named network and controlled foreign companies that are not publicly listed.

Treasury describes the A7 Network as a shadow banking network with ties to Russia that has been used by the Iranian regime to evade sanctions. Treasury states that Ilan Mironovich Shor leads the network and characterizes him as a sanctioned and convicted fraudster. OFAC first designated Shor on October 26, 2022.

The A7 Network itself is a single OFAC sanctions-list entry tagged as a transnational criminal organization under Executive Order 13581, as amended by Executive Order 13863. This distinction matters because the October 1 action did not add a newly published group of named A7 individuals. Separate Iran-related designations announced that day were not part of the A7 Network action.

For US persons, property and interests in property of the A7 Network that are in the United States, or within the possession or control of US persons, are blocked and must be reported to OFAC. Treasury’s description explicitly includes transactions involving Sub-Agents acting for or on behalf of the A7 Network.

The regulatory architecture has two different timelines:

Measure Authority Status on October 5, 2026 Scope
OFAC designation of A7 NETWORK Executive Order 13581, as amended by Executive Order 13863 Effective October 1, 2026 A7 Network property and transactions involving Sub-Agents acting for or on its behalf
FinCEN proposed 31 CFR 1010.668 Section 9714(a) of the Combating Russian Money Laundering Act Proposed rule published October 5, 2026, comments due November 4, 2026 Transmittals of funds involving any A7 Network Sub-Agent
FinCEN alert FIN-2026-Alert007 FinCEN alert Issued October 1, 2026 Red flags, reporting expectations, A7A5 exposure indicators
Suspicious activity report keyword FIN-2026-A7NETWORK Available immediately SARs related to the FinCEN alert

The proposed FinCEN measure is not a Section 311 action. FinCEN used section 9714(a) and concluded that transactions involving any A7 Network Sub-Agent constitute a class of transactions of primary money laundering concern in connection with Russian illicit finance. FinCEN selected the sixth special measure, a prohibition on transmittals of funds, after determining that the first five special measures would be insufficient.

Why does FinCEN’s Sub-Agent model matter more than a conventional token blacklist?

FinCEN’s Sub-Agent model matters because it regulates exposure to companies controlled by the A7 Network, including companies not publicly identified, rather than relying only on a static public list of wallets or legal entities. A covered institution must therefore assess ownership, control, transaction behavior, service relationships, and newly disclosed information instead of treating a public address screen as a complete sanctions-control system.

FinCEN defines a Sub-Agent as a company operating outside the United States that is controlled by the A7 Network. The known Sub-Agent list will not be public. FinCEN intends to distribute it to covered institutions through its secure FI Portal, while allowing Sub-Agents to petition for reconsideration.

This creates a difficult asymmetry for crypto compliance teams. A public blockchain can reveal direct interactions with known contracts or addresses, but a public chain does not establish who administers an address, who controls a corporate counterparty, or whether an OTC desk acts for a controlled Sub-Agent. Blockchain attribution is useful evidence, not a substitute for sanctions due diligence.

In our experience auditing smart-contract systems at Soken, compliance controls fail when a project treats an address list as the entire risk model. Effective controls combine on-chain tracing, contract-level asset identification, ownership and control checks, counterparty escalation, and documented decisions for edge cases.

The A7 Network’s operating footprint illustrates why the Sub-Agent issue is material. FinCEN states that Sub-Agents included hundreds of companies with accounts at about 435 financial institutions in at least 83 countries. FinCEN identifies company formation activity in Hong Kong, Indonesia, the Kyrgyz Republic, Seychelles, Turkiye, and the UAE.

For a virtual asset service provider, DeFi interface operator, stablecoin issuer, bridge provider, custodian, or protocol treasury, a practical control framework should distinguish four questions:

  1. Asset identification: Does the activity involve A7A5, a derivative token, or a wrapped token pegged to A7A5?
  2. Address administration: Is an account or crypto address administered by or for an A7 Network Sub-Agent?
  3. Counterparty relationship: Does an OTC broker, market maker, payment intermediary, or customer show indicators of acting for a Sub-Agent?
  4. Ownership and control: Does the OFAC 50 percent rule block an entity even where the entity itself is absent from a public list?

The OFAC 50 percent rule is central here. Entities owned directly or indirectly, individually or in the aggregate, 50% or more by blocked persons are themselves blocked. Foreign persons are also prohibited from causing US persons to violate sanctions, while civil penalties operate on a strict-liability basis.

Teams building transaction controls or sanctions-aware smart-contract integrations can incorporate this type of operational review into a broader technical security and development engagement. Compliance decisions affecting onboarding, product restrictions, terms, and licensing may also require a separate legal and regulatory review.

How did A7A5 function within the A7 Network’s settlement structure?

A7A5 functioned as a ruble-backed internal bridging asset that mirrored fiat settlement activity, allowing the A7 Network to move value between domestic Russian payments and international transfers through its Sub-Agent structure. FinCEN states that A7A5 was used as a non-freezable bridge into more widely accepted digital assets, including USDT, before conversion into customers’ fiat currency.

A7 launched in September 2024 as a purpose-built sanctions-evasion mechanism created by Ilan Shor and Russia’s state-owned Promsvyazbank, or PSB. FinCEN states that A7 LLC, A71 LLC, and A7 Agent LLC are jointly owned by Shor and PSB.

A7A5 is issued by Kyrgyz Republic-registered Old Vector LLC, an A7 Network entity. The stablecoin was advertised as backed by ruble deposits held at PSB, and its token contracts were created in late January 2025. FinCEN published the official A7A5 contract addresses on Tron and Ethereum:

Blockchain A7A5 contract address Compliance relevance
Tron TLeVfrdym8RoJreJ23dAGyfJDygRtiWKBZ Official A7A5 contract identified by FinCEN
Ethereum 0x6fa0be17e4bea2fcfa22ef89bf8ac9aab0ab0fc9 Official A7A5 contract identified by FinCEN

The token’s on-chain volume should not be read as conventional economic throughput. FinCEN identifies at least $179.1 billion in A7A5 transactions between February 2025 and June 2026, while explaining that internal transfers helped the network maintain a balanced ledger. Reporting cited by FinCEN also described circular transfers as a meaningful component of reported A7A5 activity.

A7 Network Sub-Agents reportedly handled more than $17 billion in fiat payments over a different period, from January 2025 through June 2026. That amount refers to bank-account payments through Sub-Agents, while the $179.1 billion figure tracks gross on-chain A7A5 movement. Compliance teams should preserve this distinction in board reporting, risk assessments, and investigative narratives.

The relationship between A7A5 and sanctioned exchange infrastructure also evolved. A US Secret Service-led operation took down Garantex on March 6, 2025 and froze about $26 million in crypto. Garantex customers later regained access through successor exchange Grinex using A7A5. On August 14, 2025, OFAC designated Grinex, several related companies including A7 and Old Vector, and stated that A7A5 was blocked property because of Old Vector’s interest.

After Grinex was breached on April 16, 2026 and reportedly lost about 1 billion rubles, A7A5 activity became concentrated in unhosted wallets. FinCEN treats that migration as an indicator of movement away from named sanctioned exchanges, not as a reduction in the need for controls.

Which transaction patterns should Web3 teams investigate now?

Web3 teams should investigate direct A7A5 exposure, wrapped or derivative A7A5 assets, stablecoin flows to suspected Sub-Agents, unexplained OTC growth, and trade-related stablecoin payments involving oil, military, or dual-use goods. FinCEN’s alert makes clear that risk assessment must extend beyond the native Tron and Ethereum token contracts into intermediaries and cross-chain representations.

The red flags are operationally useful because they link blockchain behavior to financial-crime context. A token transfer alone does not prove prohibited conduct, yet a transfer can become highly material when combined with wallet administration evidence, customer information, trade-payment narratives, or unusual liquidity sourcing.

FinCEN indicator What to examine Relevant A7 Network context
Exposure to A7A5 Direct interaction with the Tron or Ethereum A7A5 contracts FinCEN expressly includes A7A5 as convertible virtual currency for proposed 31 CFR 1010.668
Wrapped or derivative A7A5 Bridge contracts, liquidity pools, token wrappers, and redemption routes FinCEN warns that wrapped A7A5 may appear on other chains, often through DeFi
Stablecoin transfers to suspected Sub-Agents Address clusters, beneficiaries, OTC counterparties, and account administration Proposed rule covers transmittals to or from accounts or crypto addresses administered by or for a Sub-Agent
Rapidly expanding stablecoin OTC activity Sudden volume growth, new legal entities, weak business rationale, repetitive counterparties FinCEN identifies newly created firms and rapidly expanding stablecoin traders as an A7 Network red flag
Trade payments in stablecoins Payment instructions related to oil, military goods, or dual-use goods FinCEN specifically flags these payment narratives

FinCEN acknowledges a practical limitation that crypto businesses already understand: there are few, if any, readily available methods for covered institutions to reject incoming convertible virtual currency before receipt. That limitation means institutions need procedures for post-receipt detection, account restriction, escalation, blocking analysis, notification, and evidence retention.

US persons that block A7 Network property must file initial blocking reports within 10 business days from the date property becomes blocked. Institutions filing suspicious activity reports related to the alert should use the term FIN-2026-A7NETWORK.

For protocol teams, the controls cannot be limited to wallet screening at deposit time. They should also cover withdrawal paths, redemption flows, governance-controlled treasury movements, bridge integrations, third-party liquidity providers, and any front end that facilitates asset routing. The same approach helps reduce exposure where a project has no direct custody but does control a user interface, relayer, sequencer, or other transaction-enabling service.

Soken’s research hub covers related patterns at the boundary between smart-contract design, on-chain asset tracing, and financial-crime controls. The recurring lesson is that code-level immutability does not eliminate business-layer obligations around interfaces, counterparties, controlled wallets, and operational response.

What should covered institutions and Web3 businesses do before November 4, 2026?

Covered institutions and Web3 businesses should map A7A5-related exposure, validate sanctions-screening coverage for native and wrapped assets, establish an escalation route for suspected Sub-Agent activity, and submit rulemaking comments by November 4, 2026 where the proposed prohibition affects their operations. The deadline applies to comments on the proposal, while OFAC blocking obligations for the A7 Network already apply.

A disciplined response should be specific to the A7 Network action rather than a generic sanctions refresh:

  1. Inventory direct exposure. Search transaction history, custody records, token registries, bridge routes, and treasury wallets for the identified Tron and Ethereum A7A5 contracts.
  2. Map indirect exposure. Identify wrapped-token deployments, liquidity pools, OTC desks, payment intermediaries, and customer accounts that could introduce A7A5-linked value.
  3. Refresh ownership analysis. Apply the OFAC 50 percent rule to corporate counterparties and evaluate whether a counterparty may be controlled by the A7 Network.
  4. Prepare incident handling. Define the legal, compliance, operations, and technical owners responsible for a detected A7A5 or suspected Sub-Agent event.
  5. Separate blocking from monitoring. A confirmed blocked-property scenario requires prompt blocking and reporting analysis, while an unresolved risk indicator requires documented investigation and escalation.
  6. Assess product architecture. Review whether smart contracts, bridges, interfaces, or settlement systems make it difficult to restrict known prohibited flows after detection.

The scale of the proposed rule underscores the broad operational impact. FinCEN estimates that 347,926 financial institutions would be affected, including 8,988 banks, 3,277 broker-dealers, and 332,068 money services businesses. FinCEN estimates an annual compliance burden of about 139,700 hours and about $17.74 million.

A7 rejected allegations that it worked with Iran or terrorist organizations and stated that it provides payment settlements for the Russian market. That response does not alter the immediate legal effect of the OFAC designation or the compliance work required to assess the proposed FinCEN prohibition.

Treat the A7 Network action as a test of whether sanctions controls can follow value across issuers, wallets, OTC intermediaries, unhosted addresses, and wrapped tokens rather than stopping at an initial token contract. The concrete next step is to run an A7A5-specific exposure review across treasury, custody, bridge, and liquidity-provider records before the November 4, 2026 comment deadline.

For Web3 businesses, the deeper issue is architectural: a system that can trace direct A7A5 transfers but cannot investigate administered addresses, derivative assets, or business counterparties has only partial coverage. Building those decision points into product operations now is more reliable than attempting to reconstruct control ownership after a flagged transfer arrives.

Article author
Angelina Manko
Head of Legal & Regulatory Affairs

Frequently Asked Questions

What are the A7A5 sanctions?

On October 1, 2026, Treasury designated the Russia-linked A7 Network as a significant transnational criminal organization. The coordinated A7A5 sanctions action imposes immediate OFAC blocking requirements and addresses activity connected to A7A5, including crypto transactions and controlled foreign Sub-Agents.

What does the $179.1 billion A7A5 figure mean?

FinCEN identified at least $179.1 billion in gross on-chain A7A5 stablecoin movement from February 2025 through June 2026. More than 180 entities processed A7A5 transactions within that figure. The $179.1 billion measures gross token movement, not trade value.

Who are the A7 Network Sub-Agents covered by the action?

Non-public A7 Network Sub-Agents are controlled foreign Sub-Agents whose identities may evolve. The proposed A7A5 transfer prohibition would reach fiat and crypto transactions involving them, expanding compliance exposure beyond identifiable A7 Network entities under the coordinated action.

Which transaction types create A7A5 compliance exposure?

The A7A5 action identifies compliance exposure involving convertible virtual currency, wrapped assets, OTC counterparties, and administered crypto addresses. A7A5-related screening must account for these transaction pathways alongside identifiable A7 Network entities and controlled foreign Sub-Agents.

How do OFAC blocking requirements differ from the proposed A7A5 transfer prohibition?

A7A5 sanctions combine immediate OFAC blocking requirements with a proposed transfer prohibition. The blocking requirements apply under the coordinated action, while the proposed measure would reach fiat and crypto transfers involving non-public A7 Network Sub-Agents.

Chat